8b069cc93f
CI & Build / Python lint (push) Successful in 3s
CI & Build / integration (push) Successful in 21s
CI & Build / TypeScript typecheck (push) Successful in 49s
CI & Build / Python tests (push) Successful in 57s
CI & Build / Build & push image (push) Successful in 1m5s
Run 2888 failed with 7 tests down, both causes mine. The real problem was a design flaw, not the tests: readable_notes_clause and browsable_notes_clause each opened their own DB session to fetch the caller's group ids. That made them unmockable at the call site, so every unrelated service test suddenly had to know they existed and stub them — four modules broke the moment a service started calling one, and one of my own stubs patched the wrong name (readable_* where the code had moved to browsable_*). Fixed at the root: group membership is now a SUBQUERY rather than a fetched list, so both clauses are synchronous pure functions with no session. One fewer round-trip per query, membership folded into the statement the caller was already running, and nothing for callers' tests to mock. The "no groups means no group arm" special case disappears too — an empty subquery simply matches nothing. Also: _fake_note in the process tool tests had no real user_id, so its auto-MagicMock attribute reached session.get(User, ...) through the new provenance check and SQLAlchemy rejected it. The fixture now takes a real user_id defaulting to the bound caller, which makes "is this shared?" meaningful, and gains a case asserting another user's process comes back flagged. Test assertions on compiled SQL are deliberately loose about formatting: the local env has no SQLAlchemy (rule #10), so they check that the arms exist rather than guessing at exact rendering. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RLwAaV4DQEmVyn496HnEvt
105 lines
4.2 KiB
Python
105 lines
4.2 KiB
Python
"""The two ACL predicates behind list queries.
|
|
|
|
`get_note_permission` answers "may I read THIS note?" one row at a time, which a
|
|
list query can't use. These express the same resolution as set membership. They
|
|
are pure SQL builders — group membership is a subquery rather than a fetched
|
|
list, so they need no session and callers' unit tests need not know they exist.
|
|
|
|
Two scopes, deliberately different (decision note 2094):
|
|
readable_* — everything the ACL permits, for explicit acts (a typed search, a
|
|
fetch by id).
|
|
browsable_* — owner + project access only, for passive surfaces (browse lists,
|
|
facet counts, the process→skill manifest).
|
|
|
|
Assertions compile each clause to SQL and inspect its shape.
|
|
"""
|
|
import pytest
|
|
|
|
from scribe.services.access import browsable_notes_clause, readable_notes_clause
|
|
|
|
|
|
def _sql(clause) -> str:
|
|
return str(clause.compile(compile_kwargs={"literal_binds": True}))
|
|
|
|
|
|
def _read(user_id: int = 7) -> str:
|
|
return _sql(readable_notes_clause(user_id))
|
|
|
|
|
|
def _browse(user_id: int = 7) -> str:
|
|
return _sql(browsable_notes_clause(user_id))
|
|
|
|
|
|
# --- read scope --------------------------------------------------------------
|
|
|
|
def test_read_scope_covers_ownership_and_every_share_path():
|
|
sql = _read()
|
|
assert "notes.user_id = 7" in sql # 1. ownership
|
|
assert "note_shares" in sql # 2/3. direct or group note share
|
|
assert "notes.project_id IN" in sql # 4. inherited from a shared project
|
|
assert "project_shares" in sql
|
|
|
|
|
|
def test_read_scope_resolves_group_membership_in_sql():
|
|
"""Group ids are a subquery, not a pre-fetched list — that's what keeps this
|
|
a pure function with no session of its own."""
|
|
sql = _read()
|
|
assert "group_memberships.user_id = 7" in sql
|
|
# Both the note-level and project-level share lookups consult it. Count FROM
|
|
# clauses rather than bare occurrences — each rendered subquery names the
|
|
# table in SELECT, FROM and WHERE — and compare loosely, since the assertion
|
|
# is about the arms existing, not about SQLAlchemy's formatting.
|
|
assert sql.count("FROM group_memberships") >= 2
|
|
assert _browse().count("FROM group_memberships") >= 1
|
|
|
|
|
|
def test_read_scope_is_never_the_whole_table():
|
|
"""Guard against the predicate degrading to always-true, which would expose
|
|
every user's notes to every other user."""
|
|
sql = _read().lower()
|
|
assert " true" not in sql
|
|
assert "1 = 1" not in sql
|
|
|
|
|
|
# --- browse scope: the trust boundary ---------------------------------------
|
|
|
|
def test_browse_scope_excludes_direct_note_shares():
|
|
"""The whole point of the narrower scope. If `note_shares` leaks in here, a
|
|
record someone shared one-to-one with the operator lands in their own browse
|
|
list, facet counts and skill manifest as though they had recorded it."""
|
|
assert "note_shares" not in _browse()
|
|
|
|
|
|
def test_browse_scope_keeps_ownership_and_project_access():
|
|
sql = _browse()
|
|
assert "notes.user_id = 7" in sql # your own records
|
|
assert "project_shares" in sql # a project shared with you
|
|
assert "projects" in sql # a project you own
|
|
|
|
|
|
def test_browse_scope_is_strictly_narrower_than_read_scope():
|
|
"""Browse must never surface something read scope wouldn't also allow, or a
|
|
list could show a record the caller cannot then open."""
|
|
browse, read = _browse(), _read()
|
|
assert "note_shares" in read and "note_shares" not in browse
|
|
for arm in ("notes.user_id = 7", "project_shares"):
|
|
assert arm in browse and arm in read
|
|
|
|
|
|
def test_browse_scope_is_never_the_whole_table():
|
|
sql = _browse().lower()
|
|
assert " true" not in sql
|
|
assert "1 = 1" not in sql
|
|
|
|
|
|
@pytest.mark.parametrize("clause_fn", [readable_notes_clause, browsable_notes_clause])
|
|
def test_clauses_are_pure_builders(clause_fn):
|
|
"""Synchronous and side-effect free — no coroutine, no session of their own.
|
|
|
|
This is the property that keeps them usable: when they opened their own
|
|
session, every unrelated service test had to know they existed and stub them,
|
|
and four test modules broke the moment a service started calling one."""
|
|
import inspect
|
|
assert not inspect.iscoroutinefunction(clause_fn)
|
|
assert _sql(clause_fn(7)) # builds without touching a database
|